Privacy Policy
LAST UPDATED · 22 JUNE 2026
This Privacy Policy explains how Hello by Flow Communications Pvt. Ltd. ("Hello by Flow") collects, uses, stores, and shares your personal data when you use our Service. We are committed to compliance with the Digital Personal Data Protection Act, 2023 (DPDPA) in India and the EU General Data Protection Regulation (GDPR) where applicable.
1. Data we collect
Account data
- Name, work email, password (hashed with bcrypt), workspace name, role.
KYC documents (required by DoT/TRAI)
- Business accounts: Certificate of Incorporation, GST/PAN, authorised signatory ID.
- Individual accounts: Aadhaar, Passport, Driving Licence, or Voter ID (front + back), address proof, optional selfie.
Service data
- Call metadata (caller, callee, duration, direction, status), call recordings (only when explicitly enabled by the agent), SMS content, contacts you import, IVR flow definitions, analytics events.
Device & log data
- IP address, browser user-agent, timestamps, error logs.
2. Purposes of processing (DPDPA Sec. 4)
- To provide the Service you signed up for (lawful basis: contract performance).
- To comply with DoT/TRAI telecom regulations, anti-fraud screening, and CAF retention.
- To bill you and prevent payment fraud.
- To improve product quality (aggregated, de-identified analytics only).
3. Data Principal rights (DPDPA Sec. 11–14)
You may at any time:
- Access your personal data (Settings → Profile or write to dpo@hellobyflow.com).
- Correct inaccurate data.
- Erase data (subject to legal retention obligations under the Information Technology Act, 2000 and CAF rules — call detail records retained for 12 months).
- Withdraw consent — your account is deactivated within 7 days.
- Lodge a grievance with our DPO (see Section 8).
4. Sharing
We share data only with:
- Sub-processors: MongoDB Atlas (database hosting, India region), AWS (storage), Twilio (carrier connectivity).
- Law enforcement: on receipt of a lawful order under the IT Act or CrPC. We publish a transparency report annually.
- Never with advertisers. We do not sell your data.
5. International transfers
Personal data of Indian Data Principals is stored on infrastructure located within India. Limited metadata may be processed in approved jurisdictions (Singapore, EU) under standard contractual clauses.
6. Retention
- Account data: while your account is active + 30 days post-termination.
- KYC documents: 5 years post-termination (DoT requirement).
- Call Detail Records (CDR): 12 months (DoT requirement).
- Call recordings: as long as you keep them, deleted within 7 days of account termination.
7. Security
Encryption in transit (TLS 1.3), at rest (AES-256). Annual penetration testing. SOC 2 Type II audited. Bcrypt password hashing. Brute-force lockouts. Role-based access control.
8. Grievance Officer (DPDPA Sec. 13)
Data Protection Officer: dpo@hellobyflow.com
Hello by Flow Communications Pvt. Ltd., Bengaluru, Karnataka, India.
We respond to all grievances within 30 days.
9. Children
The Service is not intended for users under 18. We do not knowingly collect data from minors.
10. Updates
Material changes will be notified via email and in-app banner 30 days in advance.
